Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-92106
  • Hex/lazy_html
  • github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS 16 hours ago
  • Fix available
  • Severity - 2.3 (Low)
EEF-CVE-2026-93477
  • Hex/ash
  • github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash 19 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-97724
  • github.com/software-mansion/react-native-reanimated
See record for full details yesterday
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-53493
  • github.com/containerd/containerd
Containerd has image-pull DoS via crafted OCI index graph amplification yesterday
  • No fix available
  • Severity - 6.9 (Medium)
CVE-2026-97636
  • github.com/apache/airflow
Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key yesterday
  • Fix available
CVE-2026-93353
  • github.com/9001/copyparty
copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers yesterday
  • No fix available
  • Severity - 6.0 (Medium)
CVE-2026-48543
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description yesterday
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48542
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field yesterday
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48541
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field yesterday
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-48540
  • github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title yesterday
  • No fix available
  • Severity - 5.1 (Medium)
CVE-2026-96883
  • github.com/aws/pgcollection
Type confusion in AWS pgcollection allows remote code execution yesterday
  • No fix available
  • Severity - 8.7 (High)
CVE-2026-57440
  • github.com/starcitizenwiki/mediawiki-extensions-embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled yesterday
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-48073
  • github.com/docmost/docmost
Docmost: Page export can include restricted same-space attachments through forged attachmentId yesterday
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-52853
  • github.com/docmost/docmost
Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER yesterday
  • Fix available
  • Severity - 5.2 (Medium)
CVE-2026-61823
  • github.com/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute yesterday
  • Fix available
  • Severity - 7.3 (High)
CVE-2026-48072
  • github.com/docmost/docmost
Docmost: Public image fileName path traversal leads to unauthorized local file read yesterday
  • Fix available
  • Severity - 5.3 (Medium)